Impact
An unauthenticated attacker can construct a Cookie header containing boundary ASCII control characters that cause the Coraza cookie parser to index or drop cookie names in a manner inconsistent with the application’s backend parser. This discrepancy enables the attacker to make REQUEST_COOKES or REQUEST_COOKIES_NAMES rules miss the attacker’s data, effectively bypassing security checks that rely on accurate cookie extraction. The flaw stems from the internal : cookies.ParseCookies function handling control characters differently than several backend parsers and is a product of improper input validation (CWE‑436).
Affected Systems
The vulnerability affects the OWASP Coraza WAF library, specifically versions earlier than 3.8.1. Users running any Coraza deployments that rely on the internal cookie parser before the 3.8.1 release are exposed to this flaw.
Risk and Exploitability
The severity as scored by CVSS is 4, indicating moderate impact. The EPSS score is not available and the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires the attacker to send a crafted HTTP request with the confusing cookie header; it does not require authentication and does not provide code execution or other privilege escalation. The likelihood of exploitation is moderate to low, but the potential to bypass key WAF rules warrants timely remediation.
OpenCVE Enrichment